Skip to content

Series

ShellBags in investigations

4 posts in this series. Read them in order or jump to any one.

  1. ShellBags USB Forensics: A Worked Investigation Example

    A fictional case, step by step: ShellBags show a service account browsing a ZIP toolkit, a finance share and a USB drive. What they prove, and what they do not.

  2. ShellBags and ZIP Files: Proving Archive Browsing

    How ShellBags record browsing inside ZIP files and other archives in Explorer, what the compressed folder items contain, and how to interpret archive paths.

  3. ShellBags Deleted Folders: Proving a Folder Existed

    Use ShellBags to show a deleted or renamed folder existed: read its path, embedded times and MFT entry and sequence, then confirm with the $MFT and USN.

  4. ShellBags Limitations and Anti-Forensics: What to Watch

    What ShellBags cannot prove, what never creates them, how cleaners like PrivaZer or CCleaner remove them, and the traces deletion and tampering leave.

All posts in this series